ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    1. Topics
    2. Tags
    3. hacked
    Log in to post
    • All categories
    • JaredBuschJ

      How can I see what process is updating a file

      Watching Ignoring Scheduled Pinned Locked Moved Unsolved IT Discussion wordpress vultr wordfence chattr hacked phpmyadmin xhprof cockpit ubuntu 18.04
      2
      2 Votes
      2 Posts
      610 Views
      black3dynamiteB

      You can trying using auditd to audit the file.

      sudo apt-get install auditd

      Running sudo auditctl -l by default show no rules

      Create a temporary rule to audit changes to index.php

      sudo auditctl -w /var/www/html/index.php -p rwxa # -p = read, write, execute, attributes

      Run sudo auditctl -l will show the rule that was created.
      Now run sudo ausearch -f index.php | more to show what's touching index.php
      or sudo tail -f /var/log/audit/audit.log | grep index.php.

    • DashrenderD

      Weird thing on O365 account

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion hacked dashrender
      35
      0 Votes
      35 Posts
      3k Views
      KellyK

      @Dashrender said in Weird thing on O365 account:

      @Kelly said in Weird thing on O365 account:

      @Dashrender said in Weird thing on O365 account:

      Alright, the user has confirmed that she made changes yesterday, and those change could associate with GMT based time.

      Anyone know if the logs are only/mainly in GMT?

      Almost all O365 logs are UTC 0 regardless of the timezone of the server or requestor.

      yeah, OK that makes the time line up for when the user added the rules, I'm just curious why it took MS 6 hours to send the noticed of alert?

      They batch some of their processes, so it may have had to wait for the group to run rather than being on demand/occurrence.

    • DashrenderD

      Email investigation - have we been hacked?

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion email hacked dashrender
      11
      0 Votes
      11 Posts
      961 Views
      DashrenderD

      @IRJ said in Email investigation - have we been hacked?:

      @Dashrender said in Email investigation - have we been hacked?:

      one of the addresses is for an @ameritrade.com address, but only for one person. I have yet to find any connection via google searches between this person and ameritrade.... so I'm not sure why this was tried?

      Thoughts?

      You dont have that data either, right?

      What do you mean?

    • WrCombsW

      When Anti-Virus Companies Get Hacked: Symantec, Trend Micro, and Intel McAfee

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion antivirus hacked breach symantec av trend micro mcafee intel
      10
      0 Votes
      10 Posts
      1k Views
      scottalanmillerS

      @Dashrender said in When Anti-Virus Companies Get Hacked: Symantec, Trend Micro, and Intel McAfee:

      I can't recall if the bad ccleaner was signed or not?

      Even if it was, that would be a Microsoft compromise. This is about the AV vendors getting hacked.

    • wrx7mW

      TurboTax Hit with Cyberattack, Tax Returns Compromised

      Watching Ignoring Scheduled Pinned Locked Moved News hacked cyber security cybercrime compromised taxes
      10
      3 Votes
      10 Posts
      1k Views
      JaredBuschJ

      @dafyre said in TurboTax Hit with Cyberattack, Tax Returns Compromised:

      @JaredBusch said in TurboTax Hit with Cyberattack, Tax Returns Compromised:

      @wrx7m said in TurboTax Hit with Cyberattack, Tax Returns Compromised:

      @dafyre Yes. Exactly. That is why I use different random passwords from a generator for anything of any importance.

      My random password generator of choice (http://correcthorsebatterystaple.net) :
      3fc1f8b0-afea-415d-a25d-3ac4a50257f7-image.png

      I just use Bitwarden's generator if I need one.

      I like this because, when I rarely actually need to type one in, I can easily do so.

      Mixing up the special characters (see separator box) makes it more than just words.
      Separator: 213456789!@#$%
      b2acbe68-5cf5-4aa9-8a8e-9a38413db100-image.png

    • wrx7mW

      Website Security Auditor Recommendations Wanted

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion wordpress hacked website security security audit aws audit
      5
      2 Votes
      5 Posts
      723 Views
      dbeatoD

      YOu can also do a free test from Qualys
      https://www.qualys.com/free-services/
      https://www.qualys.com/community-edition/

    • JaredBuschJ

      OwnCloud forums compromised

      Watching Ignoring Scheduled Pinned Locked Moved News owncloud forum hacked
      4
      3 Votes
      4 Posts
      939 Views
      scottalanmillerS

      ownedCloud.

    • stacksofplatesS

      Equifax Again

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion equifax hacked
      15
      3 Votes
      15 Posts
      2k Views
      DustinB3403D

      @aaronstuder I watched that video some time ago, such a good channel.

    • gjacobseG

      Business Stuck With Massive Bill After Phones Hacked

      Watching Ignoring Scheduled Pinned Locked Moved News pbx phone system hacked security
      15
      3 Votes
      15 Posts
      2k Views
      scottalanmillerS

      I believe that @QuixoticJeremy is doing a talk about something kind of similar.

    • 1 / 1